Authenticating Data Based on Certificates
Abstract
A method for modifying an electronic device ( 10 ) using authenticated data from a data host ( 12 ) comprises the steps of the a signing service ( 13 ) digitally signing the data with a digital signature using a signature private key of a signature key pair and providing the signed data to the data host ( 12 ), the electronic device ( 10 ) retrieving the signed data from the data host ( 12 ), the electronic device ( 10 ) confirming a signature public key of the signature key pair using a certificate of a certificate authority ( 14 ), the electronic device ( 10 ) checking whether the certificate is valid, and the electronic device ( 10 ) confirming the digital signature and thus authenticity of the data using the signature public key. The certificate includes an iteration number, and the electronic device ( 10 ) checks whether the certificate is valid based on the iteration number.
Claims
exact text as granted — not AI-modified1 . A method for modifying an electronic device using authenticated data from a data host, the method comprising the steps of
a signing service digitally signing the data with a digital signature using a signature private key of a signature key pair and providing the signed data to the data host; the electronic device retrieving the signed data from the data host; the electronic device confirming a signature public key of the signature key pair using a certificate of a certificate authority; the electronic device checking whether the certificate is valid; and the electronic device confirming the digital signature and thus authenticity of the data using the signature public key,
wherein the certificate includes an iteration number and in that the electronic device checks whether the certificate is valid based on the iteration number.
2 . The method according to claim 1 ,
wherein at least a second digital signature and at least a second certificate are used to confirm authenticity of the data, with the second certificate also checked for validity based on the iteration number or another iteration number.
3 . The method according to claim 1 ,
wherein the electronic device stores a minimal iteration number that the certificate's iteration number needs to match or exceed in order to be accepted as being valid.
4 . The method according to claim 1 ,
wherein certificates of the certificate authority are validated by a chain of higher-level certificate authorities with a root certificate authority at the origin of the chain, wherein in particular the electronic device stores a root certificate of the root certificate authority.
5 . The method according to claim 1 ,
wherein the electronic device stores a product identifier corresponding to a designated certificate authority among a plurality of certificate authorities that include a certificate authority responsible for each possible product identifier.
6 . The method according to claim 5 ,
wherein the electronic device ( 10 ) checks whether the certificate matches the product identifier.
7 . The method according to claim 5 ,
wherein the root certificate authority authenticates a plurality of certificate authorities that include a certificate authority responsible for each possible product identifier.
8 . The method according to claim 1 ,
wherein, in order to invalidate or revoke a certificate, a new certificate authority is set up, replacing the certificate authority, and issuing certificates with iteration number increased.
9 . The method according to claim 8 ,
wherein the new certificate authority is authenticated by the root certificate authority.
10 . The method according to claim 9 ,
wherein the authentication by the root certificate authority takes place offline and/or wherein the root certificate authority is always offline.
11 . The method according to claim 8 ,
wherein, following revocation of a certificate and increase of the iteration number, the electronic device is updated via authenticated data retrieved from the data hos), the update including storage of a new minimal iteration number.
12 . A data host and certification network for providing authenticated data to an electronic device, the certification network comprising a certificate authority configured to issue a certificate confirming authenticity of a signature public key of a signature key pair and a signing service for digitally signing the data with a digital signature using a signature private key of the signature key pair and the data host providing direct or indirect access for the electronic device to retrieve the signed data, wherein the certificate includes an iteration number usable in a check whether the certificate is valid.
13 . An electronic device comprising an interface for at least indirectly connecting the electronic device to a data host, a memory for storing data, and a control unit configured to
retrieve authenticated data via the interface and to store the data in the memory, the data digitally being signed by a signing service with a digital signature using a signature private key of a signature key pair; verify a signature public key of the signature key pair using a certificate of a certificate authority; check whether the certificate is valid; confirm the digital signature and thus authenticity of the data using the signature public key; and if authenticity of the data is confirmed, modify the future control of the electronic device based on the data, wherein the certificate includes an iteration number and the control unit is further configured to check whether the certificate is valid based on the iteration number.
14 . An electronic device according to claim 13 that is configured as a sensor.
15 . A system comprising at least one data host and certification network according to claim 12 and at least one electronic device according to claim 13 .Join the waitlist — get patent alerts
Track US2024333529A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.